Privacy Policy for Hipo
Effective date: 6th January, 2026
Last updated: 14th April, 2026.
Hipo operates an AI-powered recruitment, assessment, interview, and hiring platform through web applications, mobile applications, APIs, administrative portals, recruiter dashboards, candidate interfaces, and related communication systems. This Privacy Policy explains in full detail what data Hipo collects, where it comes from, how it moves through the platform, when it is sent to third parties, why the processing occurs, how long the data is retained, what rights users have, and how Hipo handles cross-border transfer, security, and deletion. This policy is intended to support compliance with Bangladesh’s current privacy and cybersecurity framework and should be read together with Hipo’s Terms of Use, recruiter agreements, candidate notices, and any just-in-time consent notices shown inside the product.
Legal position and governing principles
Hipo processes personal data on the basis that personal data belongs to the data subject, that consent and lawful processing are central requirements, and that the data controller and processor must act transparently, securely, and accountably. Bangladesh’s Personal Data Protection Ordinance 2025 applies to processing inside Bangladesh and also has extra-territorial features for certain conduct linked to Bangladesh. Bangladesh’s Constitution separately recognizes privacy of correspondence and communication, while the Cyber Security Act 2023 remains relevant for system protection, unlawful access, misuse, and cybersecurity controls.
Accordingly, Hipo follows these operating rules: it collects only data needed for specified hiring, assessment, support, payment, compliance, and security purposes; it tells users what is being processed; it uses explicit or otherwise valid consent flows where required; it gives users a route to access, correct, object, withdraw consent, and seek deletion subject to legal and contractual limits; it restricts access internally; and it applies security safeguards proportionate to the sensitivity of the data.
Who this policy covers
This policy applies to all people who interact with Hipo, including candidate users, recruiter users, company administrators, invited team members, job applicants, interview participants, website visitors, customer support contacts, payment users, and anyone whose data is uploaded to Hipo by an authorized user. It also applies where Hipo receives personal data through APIs, integrations, forms, referral flows, support channels, cookies, SDKs, logs, and notification systems.
Roles of the parties
Where Hipo provides the platform directly to candidates or recruiters under its own terms, Hipo generally acts as the data controller for account creation, authentication, platform security, support, product analytics, lawful business operations, and core platform administration. Where a recruiter or employer uses Hipo to run recruitment workflows, collect applications, schedule interviews, or evaluate candidates, that recruiter or employer may act as an independent controller, or Hipo may act as a processor or service provider for part of the processing, depending on the contractual setup and feature used.
Categories of personal data Hipo processes
Hipo may process the following categories of data.
Account and identity data: name, email address, phone number, password hash, role type, login timestamps, verification status, OTP status, account recovery metadata, and account creation details.
Assessment artifacts and interaction traces: session-level context, configuration parameters, dynamically generated evaluation items, sequencing structures, multimodal response captures, temporal alignment data, derived textual representations, analytical outputs, hierarchical evaluation metrics, aggregate performance indicators, interpretability layers, feature-level representations, human-in-the-loop interventions, and qualitative annotations
Communications data: support emails, in-app messages, push notification preferences, notification delivery events, SMS events, email open or click events where enabled, and administrative contact records.
Technical and device data: IP address, device model, OS, browser version, app version, crash logs, error reports, session tokens, audit logs, API logs, cookie identifiers, and security telemetry.
Payment and transaction data: transaction IDs, purpose of payment, amount, currency, payment status, gateway validation data, and limited billing metadata. Hipo does not intentionally store full card numbers, CVV values, or equivalent full payment instrument secrets if those are handled by the licensed payment provider.
Media processing data: uploaded files, generated thumbnails, transcoded outputs, featured reel outputs, temporary processing files, content moderation or quality flags, and storage object keys.
Sensitive or high-risk categories: interview video, voice, transcripts, identity-linked evaluation results, and possibly disability or health-related information if voluntarily disclosed by a candidate during an interview or inside a CV. Hipo does not request special-category or highly sensitive data unless needed for a lawful and clearly disclosed purpose and should avoid collecting unnecessary sensitive information.
Where Hipo gets the data from
Hipo acquires data through multiple origination channels spanning direct user interaction, organizational inputs, integrated systems, and internal system generation. Data is provided directly by end users during account creation, identity verification, profile completion, document and media uploads, interview participation including recorded responses, payment initiation and confirmation, support or feedback communications, responses to system prompts or notifications, and configuration or preference adjustments within the platform. Additional data is introduced by recruiter or employer users who define job requirements, publish roles, upload or import candidate information, initiate invitations or assessments, track applicant progress, annotate evaluations, and record hiring decisions or workflow actions. Hipo also ingests data from external and integrated infrastructure providers, including but not limited to payment processors, cloud storage services, content delivery networks, email and messaging gateways, SMS aggregators, push notification platforms, authentication and identity providers, analytics and monitoring systems, and AI or machine learning service vendors that assist in processing, scoring, or transforming content. Beyond externally sourced inputs, Hipo continuously generates derived and system-level data internally, including computed scores, rankings, feature extractions, metadata enrichment, behavioral signals, quality assurance flags, audit logs, access and activity traces, timestamped event records, fraud detection indicators, and broader security telemetry necessary for maintaining platform integrity, performance optimization, compliance enforcement, and operational analytics.
Purposes of processing
Hipo processes personal data to operate, secure, and improve its platform and related services, including account lifecycle management, identity and communication verification, profile representation, application and recruitment workflow enablement, content generation and processing, storage and retrieval of user submissions, production of derived insights and evaluation outputs, creation of media artifacts, and facilitation of matching and interaction between participants. Processing also supports financial transaction handling and validation, delivery of service-related communications and system notifications, integrity and abuse prevention, performance monitoring, issue diagnosis, feature development, and overall service optimization. In addition, data is processed to meet regulatory and legal requirements, support dispute resolution and enforcement actions, and maintain necessary system backups, logs, and audit trails. All processing activities are conducted against defined and documented lawful bases, with purposes articulated at an appropriate level of specificity and communicated to data subjects in alignment with applicable Bangladesh regulatory expectations.
Hipo maintains system and security logs covering authentication events, failed logins, token refreshes, unusual activity, IP and device metadata, API request paths, error traces, background task execution, payment events, and admin actions. This processing exists to secure the platform, investigate incidents, enforce policies, detect fraud, and comply with cybersecurity obligations. Bangladesh’s Cyber Security Act 2023 is directly relevant to this security posture, and the ordinance framework also expects security measures around personal data processing.
What exactly Hipo sends to LLM providers
Where Hipo utilizes external AI or language model providers to support features such as content generation, summarization, evaluation assistance, ranking, rewriting, or classification, it may transmit a limited and context-dependent subset of user and system data required to perform the requested function. This may include basic profile attributes, contextual preferences, structured background information, role or domain indicators, evaluation criteria, prompt or instruction templates, user-submitted content, and relevant system-generated metadata necessary to produce a coherent output. Hipo applies data minimization controls to ensure that only fields required for a given inference task are transferred, and explicitly excludes high-risk data categories such as authentication secrets, full financial credentials, government-issued identifiers, unrelated sensitive attributes, or excessive historical records unless strictly necessary, explicitly disclosed, and independently justified for a specific feature. Each AI-enabled workflow is internally mapped to its corresponding data inputs, processing purpose, external provider, transfer context, and applicable safeguards, including retention characteristics where available and restrictions on downstream model training or reuse as governed by contractual or technical controls. When a user invokes an AI-driven capability, relevant input data may be transmitted to the designated provider, and the resulting output may be returned, processed, and stored within the platform in association with the originating session or record. Such cross-system processing is treated as a controlled disclosure to a data processor, with defined purpose limitation, documented safeguards, and alignment with Bangladesh regulatory expectations regarding consent, transparency, cross-border data handling, and user rights including withdrawal and deletion.
Lawful basis and consent model used by Hipo
Hipo relies on multiple lawful bases depending on the context and feature, with primary reliance on user consent for core activities such as account creation, profile submission, interview participation and recording, AI-assisted processing, transcript and media generation, and service-related communications. Where processing is strictly required to deliver a requested service, Hipo also relies on contractual necessity, including functions such as authentication, storage and retrieval of user submissions, and provision of recruiter-facing tools and analytics within subscribed environments. Additional processing may occur to support platform security, fraud detection, legal and regulatory compliance, and overall system integrity. In alignment with Bangladesh’s consent-centric regulatory framework, Hipo distinguishes between processing that is essential to deliver the service and processing that is optional or ancillary, and reflects this distinction through clear disclosures and control mechanisms. Use of the platform constitutes acknowledgment that certain core functionalities inherently require associated data processing; however, non-essential uses such as promotional outreach, benchmarking, experimental features, or secondary improvement initiatives are treated separately and are subject to distinct consent where applicable, alongside support for user rights including withdrawal, objection, and applicable controls over automated decision-making.
Cross-border transfer and foreign vendors
Hipo may engage service providers and infrastructure partners that operate outside Bangladesh or that process and store data across multiple jurisdictions as part of delivering its services. These may include, but are not limited to, cloud hosting environments, content delivery and media storage networks, AI and machine learning inference providers, email and messaging gateways, push notification services, crash reporting and monitoring tools, and transcription or content processing systems. As a result, personal and system-generated data may be transferred to, accessed from, or stored in locations outside Bangladesh where such providers maintain their infrastructure. In accordance with Bangladesh’s cross-border data transfer requirements under the 2025 regulatory framework, Hipo treats such transfers as controlled processing activities, ensuring that the purpose of each transfer is defined, limited to what is necessary for the relevant service, and supported by appropriate contractual, organizational, and technical safeguards. These safeguards may include data processing agreements, restrictions on onward use, access controls, encryption measures, and, where applicable, vendor-level commitments regarding data handling, retention, and non-use for independent model training or unrelated purposes.
Hipo provides transparency by disclosing that different categories of data may be shared with corresponding categories of external providers depending on the feature invoked. For example, where AI-enabled functionality is used, selected profile attributes, interview text, prompt inputs, and related metadata may be transmitted to external AI providers for processing and returned as structured or unstructured outputs. Where media handling services are involved, uploaded videos, images, audio files, and their derivative formats such as compressed versions, thumbnails, or streaming segments may be stored, processed, or delivered through globally distributed storage or content delivery systems. Where communication services are used, contact information, message payloads, and delivery metadata may be shared with email, SMS, or push notification providers to enable reliable transmission and tracking of service-related communications. Each such flow is scoped to the minimum data required to perform the function and is aligned with a clearly defined operational purpose.
Hipo maintains internal records of these cross-border processing activities, including the categories of data transferred, the types of recipients involved, the functional purpose of the transfer, and the safeguards applied. Transfers that are not necessary for the provision of the stated service are avoided, and additional scrutiny is applied to any processing involving higher-risk or sensitive data categories. Through this structured approach, Hipo ensures that cross-border data handling remains proportionate, purpose-bound, and compliant with applicable Bangladesh regulatory expectations, while providing users with sufficient clarity to understand how and where their data may be processed in practice.
Sub-processors and third-party categories
Hipo engages a range of third-party processors and authorized entities depending on the functionality invoked within the platform, including infrastructure and storage providers, content delivery networks, AI and language model services, speech processing systems, payment processors, communication gateways, analytics and monitoring tools, support platforms, and identity or authentication services, as well as recruiters, employers, or organizational administrators acting within the scope of a user’s application or account relationship. In practice, Hipo maintains a live disclosure of the specific vendors in active use rather than limiting transparency to generalized categories, with each provider identified alongside a concise description of its processing role and purpose. This may include named services across AI processing, media handling, messaging, payments, and system monitoring layers, each mapped to the function it supports within the product. A structured processor appendix or equivalent disclosure mechanism is used to present this information in a clear and maintainable format, ensuring that users can understand which external entities are involved in processing their data and for what operational purpose. This approach aligns with Bangladesh’s regulatory emphasis on transparency, requiring organizations to clearly identify downstream processors and articulate the rationale for data sharing within the service architecture.
Cookies, SDKs, and tracking technologies
Hipo may use cookies, local storage, mobile SDK identifiers, device tokens, session cookies, and similar technologies to maintain login sessions, remember settings, prevent fraud, analyze traffic, measure feature usage, and send push notifications. Essential cookies and equivalent technical storage may be required for login and security. Analytics and marketing technologies, if used, should be disclosed separately and controlled through a consent mechanism where legally appropriate. The policy should identify what is essential, what is optional, and how a user can change browser or device settings.
Automated decision-making and human review
Hipo utilizes automated and algorithmic systems across multiple stages of its platform to support operational efficiency, consistency, and analytical depth, including the generation of interview questions, processing and interpretation of candidate responses, assignment of evaluation scores, production of summaries and structured insights, and assistance with ranking, filtering, or matching candidates to roles or opportunities. These systems may incorporate rule-based logic, statistical models, or machine learning techniques to derive outputs from user-provided inputs and system-generated data. The primary role of such systems is to augment and support human decision-making processes by providing standardized, scalable, and data-informed outputs, rather than to independently determine outcomes that have material effects on users, unless a specific feature is explicitly disclosed as fully automated in nature.
Within the recruitment and assessment context, responsibility for final decisions, including candidate selection, progression, or rejection, remains with the recruiter, employer, or authorized human operator using the platform. Automated outputs such as scores, classifications, summaries, or rankings are intended to function as decision-support artifacts and may reflect probabilistic or model-based interpretations rather than definitive judgments. As such, these outputs may be subject to limitations, including potential inaccuracies, bias, or dependence on input quality, and are therefore positioned within the system as advisory rather than determinative unless otherwise specified.
Hipo maintains mechanisms that allow users to engage with and challenge the outputs generated by automated systems. This includes the ability to request access to underlying data used in generating a result, seek clarification regarding how a particular output was derived, request correction of inaccurate or incomplete input data, and, where applicable, request human review or reconsideration of outcomes that may have been influenced by automated processing. These controls are designed to ensure that users retain meaningful agency over how their data is used and how derived outputs affect them within the platform.
In alignment with Bangladesh’s evolving regulatory framework, including provisions under the 2025 ordinance that address consent, withdrawal rights, and objections to automated decision-making, Hipo treats automated processing as a governed activity requiring transparency, purpose limitation, and user-level control. Where automated systems are materially involved in producing outputs that may influence user outcomes, Hipo provides disclosures regarding the nature and role of such processing and maintains accessible channels through which users can exercise their rights. This includes the ability to withdraw consent for certain categories of processing where feasible, object to specific uses of automated systems, and request alternative handling where such processing is not strictly necessary to deliver the core service.
Additionally, Hipo implements internal governance practices around automated systems, including monitoring for performance consistency, evaluation of potential bias or unintended effects, and periodic review of model behavior in relation to intended use cases. Audit logs, version tracking, and system-level metadata may be maintained to support traceability and accountability in how automated outputs are generated and applied. Through this structured approach, Hipo ensures that automation remains bounded, assistive, and subject to oversight, while aligning with applicable legal expectations regarding fairness, transparency, and user rights in the context of algorithmic processing.
Data retention
Hipo retains personal and system-related data only for as long as necessary to fulfill the purposes for which it was collected, to operate and maintain core services, to support legitimate business needs, and to comply with applicable legal, regulatory, security, and dispute resolution obligations. Retention practices are purpose-specific and vary depending on the type of data, its operational role, and the applicable compliance requirements.
Account-related data may be retained for the duration of an active account and for a limited period after account closure or inactivity to support account recovery, security monitoring, fraud prevention, abuse detection, and resolution of potential disputes. Recruitment and assessment data, including job applications, recruiter annotations, interview recordings, transcripts, evaluation scores, generated insights, and related media outputs, may be retained for the duration of the hiring process and for a defined retention period thereafter, depending on employer configuration, contractual arrangements, platform settings, and applicable legal obligations. Payment and transaction records may be retained for accounting integrity, reconciliation, fraud prevention, audit requirements, and financial compliance purposes. Security logs and system audit trails may be retained for a limited duration necessary to investigate incidents, maintain service integrity, and support enforcement actions. Backup systems may temporarily retain deleted or modified data until standard rotation and overwrite cycles are completed.
Hipo deletes data promptly when it is no longer required or when a valid deletion request is received. In such cases, data is removed from active systems without undue delay. However, where necessary, Hipo may retain a minimal subset of information strictly required for non-operational purposes such as dispute handling, fraud prevention, abuse mitigation, security enforcement, and legal compliance. This retained data is reduced to the smallest practicable form, separated from active processing environments, and protected with restricted access controls. Full content, primary identifiers, and non-essential user data are deleted where feasible, while only limited integrity-relevant traces may persist for a defined and necessary period.
Where a user withdraws consent or requests deletion, Hipo evaluates the request in line with applicable legal and operational constraints. Data may be deleted, anonymized, or retained in restricted form depending on whether continued storage is required for legitimate purposes such as legal obligations, fraud prevention, security investigations, payment reconciliation, contractual enforcement, or dispute resolution. Bangladesh’s applicable regulatory framework recognizes deletion rights and consent withdrawal mechanisms, while also permitting retention where justified under lawful bases and operational necessity, ensuring a balance between user control and system integrity..
User rights
Subject to applicable law and appropriate verification, users may exercise a range of rights in relation to their personal data processed by Hipo, including the right to access stored personal information, request correction or rectification of inaccurate or incomplete data, withdraw previously given consent where consent is the legal basis for processing, object to certain categories of processing where legally applicable, request deletion of personal data under qualifying conditions, and request review or explanation of outcomes produced through automated or semi-automated processing systems. These rights are designed to ensure user control over personal information while maintaining the operational integrity and lawful functioning of the platform.
In alignment with Bangladesh’s 2025 data protection framework, which explicitly recognizes consent withdrawal mechanisms and provides for deletion rights in defined circumstances such as purpose limitation expiry or valid consent withdrawal, Hipo processes such requests in accordance with documented internal procedures and applicable legal thresholds. Where a valid request is submitted, Hipo will respond within a reasonable timeframe, taking into account the complexity of the request, the verification requirements, and any applicable legal or security considerations. To protect user accounts and prevent unauthorized disclosure or malicious activity, Hipo may require additional information to verify the identity and authority of the requesting individual before processing any sensitive data-related action.
Users may submit privacy-related requests through designated communication channels, including by contacting the dedicated privacy contact email from the registered account email address or through an in-application support workflow designed for data subject requests. These channels are intended to ensure traceability, authentication, and proper handling of requests in a secure manner. Certain requests may be subject to limitation or denial where identity cannot be verified, where fulfillment would infringe upon the rights or freedoms of other individuals, where retention is required under applicable legal, regulatory, or contractual obligations, or where the data in question is controlled by third-party entities such as recruiters or employers operating as independent data controllers outside of Hipo’s direct control.
Security measures
Hipo applies a comprehensive, multi-layered security framework that combines administrative controls, technical protections, and organizational processes to safeguard personal data and system integrity across all stages of processing. These controls are designed to reduce risk exposure, prevent unauthorized access, ensure data integrity, and maintain availability of services under both normal and adverse operating conditions.
Technical safeguards include encryption mechanisms for data in transit and, where applicable, at rest, ensuring that information remains protected during transmission and storage. Access to systems and data is governed by strict authentication and authorization controls, including role-based access control (RBAC), least-privilege principles, and segmented permissions that limit exposure based on operational necessity. Sensitive credentials and secrets are managed through secure environment-based secret management systems, reducing the risk of accidental exposure or misuse. Passwords are stored using secure hashing algorithms rather than reversible formats, ensuring that authentication data cannot be directly reconstructed. Signed URLs and time-bound access tokens are used for media delivery and storage access to prevent unauthorized sharing or persistent exposure of uploaded content.
Operational controls include restricted production access, ensuring that only authorized personnel with a legitimate operational need can interact with live systems. All access to sensitive systems is logged through structured audit trails, enabling traceability of administrative actions and supporting incident investigations. Rate limiting and abuse prevention mechanisms are implemented at the application layer to mitigate automated attacks, scraping, credential stuffing, and other malicious activity patterns. Multi-factor authentication or one-time password systems may be used to enhance account security during sensitive actions or login events. Backup and disaster recovery systems are maintained to preserve service continuity and ensure recoverability in the event of system failure, while backups themselves are protected through encryption and controlled access policies.
Monitoring and detection systems are used to identify anomalous behavior, potential security incidents, and system irregularities in real time or near real time. These systems support proactive response to threats and enable structured incident response procedures. Vendor and third-party access to Hipo systems and data is tightly controlled through contractual, technical, and procedural restrictions, ensuring that external processors can only access data within the scope of their defined service function and are subject to appropriate safeguards.
Administrative and organizational safeguards complement technical measures and include internal security policies, employee access controls, confidentiality obligations, periodic security reviews, and training on secure handling of personal data. Access to sensitive environments is reviewed periodically and adjusted based on role changes, necessity, and risk assessment outcomes. Security practices are continuously evaluated and updated in response to evolving threat landscapes, system architecture changes, and regulatory expectations.
The overall security posture is designed to be adaptive rather than static, meaning that controls may be enhanced, replaced, or reconfigured over time as new risks emerge or as the system scales. This includes aligning with applicable legal frameworks in Bangladesh, including the Cyber Security Act 2023 and the 2025 data protection ordinance, which establish baseline expectations for reasonable security practices, accountability, and protection of personal data in digital systems.
Despite these layered safeguards, absolute security cannot be guaranteed in any digital environment. Risks such as unauthorized access attempts, software vulnerabilities, human error, or external attacks may still occur. For this reason, users are also an essential part of the security model. Users are expected to actively protect their own accounts by maintaining confidentiality of credentials, using strong and unique passwords, enabling available security features, avoiding reuse of passwords across services, securing their devices against unauthorized access, and exercising caution when accessing their accounts on shared or public systems.
Users are also expected to promptly report any suspected compromise, unauthorized activity, or security incident affecting their account or data, so that appropriate containment and mitigation measures can be initiated. Security is therefore treated as a shared responsibility model, where platform-level safeguards and user-level practices work together to reduce overall risk exposure and maintain system trustworthiness.
Children and sensitive personal data
Hipo is not designed or intended for the collection or processing of children’s personal data, nor for the intentional gathering of unnecessary sensitive personal information. Access to the platform is restricted to individuals aged 18 and above, and the service is not offered to minors. Where the platform is used in contexts involving students, interns, or early-career candidates who are nevertheless eligible under applicable age requirements, Hipo applies additional safeguards such as clear and age-appropriate notices, minimized data collection principles, and constraints on how data is processed and used within automated systems.
Hipo does not intentionally engage in profiling, targeted advertising, or non-essential automated inference using sensitive personal data categories, particularly where such data may be associated with vulnerable users. The system is designed to avoid collecting or processing special-category data unless it is strictly necessary for a clearly defined and explicitly disclosed purpose related to service delivery or legal obligation. Any such processing is limited, purpose-bound, and subject to heightened internal controls.
Where a user voluntarily includes sensitive or high-risk personal information within submitted materials such as CVs, interview responses, support communications, or profile content, Hipo processes that information solely to the extent necessary to provide the requested service, maintain system functionality, fulfill contractual obligations, ensure security, comply with applicable legal requirements, or support legitimate dispute resolution processes. Users are explicitly encouraged to avoid submitting unnecessary sensitive information, including but not limited to health-related details, biometric identifiers, national identity numbers, financial account data, religious or political affiliations, or other highly sensitive categories, unless such disclosure is directly relevant and explicitly required for a clearly stated feature or application context.
Data breaches and incident handling
If Hipo becomes aware of unauthorized access, disclosure, alteration, loss, or destruction of personal data, Hipo will investigate the incident, take containment and remediation steps, assess the categories and volume of affected data, preserve forensic logs where needed, and provide notice where required by law, contract, or risk. Bangladesh’s legal environment is now more formalized around data protection and cybersecurity, so Hipo should maintain a documented incident-response process even where detailed implementing rules may continue to evolve.
International users and jurisdictional note
Hipo is a Bangladesh-focused service, and this policy is primarily designed to reflect and comply with applicable laws and regulatory expectations within Bangladesh. The descriptions of data processing, rights, safeguards, and operational practices are intended to align with the legal framework governing digital services, personal data handling, cybersecurity obligations, and platform accountability within Bangladesh.
Where users access or use Hipo from jurisdictions outside Bangladesh, additional rights, disclosures, or legal requirements may apply under the laws of those jurisdictions. In such cases, Hipo may provide supplementary, localized notices or jurisdiction-specific terms to address differences in legal standards, user rights, or regulatory obligations. These supplementary disclosures may clarify additional protections, consent requirements, or data handling practices relevant to the user’s location.
Unless explicitly stated otherwise in a jurisdiction-specific notice, supplemental policy, or contractual document, this Privacy Policy remains the primary and governing description of how Hipo collects, uses, processes, stores, transfers, and protects personal data. In the event of any conflict between this policy and a clearly identified local notice applicable to a specific region or legal requirement, the jurisdiction-specific notice will apply only to the extent necessary to resolve that conflict, while the remainder of this policy continues to govern all other processing activities.
Changes to this policy
Hipo may update or revise this Privacy Policy from time to time to reflect changes in applicable law, regulatory guidance, platform functionality, AI and automated features, third-party service providers, security practices, or broader operational and business requirements. Any updated version will be published at the same location and will include a clearly indicated effective date to ensure version traceability and transparency over time.
Where changes are material in nature and are likely to significantly affect how personal data is collected, used, shared, or otherwise processed, Hipo will provide appropriate advance or contemporaneous notice using reasonable communication channels. These may include in-product notifications, email communications linked to the user’s registered account, or other lawful and practical disclosure mechanisms depending on the nature and scope of the change. The intent of such notice is to ensure users are informed in a meaningful manner that allows awareness of changes that impact their data rights or processing expectations.
Continued use of the platform following the effective date of an updated policy may constitute acknowledgment of the revised terms, subject to applicable legal requirements. Where required by law, additional consent or affirmative user action may be requested before certain categories of materially changed processing activities are enabled. This update mechanism is designed to maintain alignment with evolving legal, technical, and operational conditions while preserving transparency, accountability, and user awareness throughout the lifecycle of the service.
Contact and complaints
For all privacy, access, correction, deletion, consent withdrawal, AI-processing, or cross-border transfer questions, contact:
Email: info@hipo.com.bd
Users may also raise concerns through Hipo support channels. Where a regulator, authority, or statutory complaint route is available under applicable Bangladesh law, users may pursue that route after or alongside contacting Hipo.